Article 5(1)a of the GDPR is simple. It sets out the first of the GDPR privacy principles: “personal data shall be processed in a lawful, fair and transparent manner in relation to the data subject”.
These means the GDPR requires organisations to process personal data lawfully, fairly, and transparently.
These are three separate but closely connected requirements.
The principle applies to all processing of personal data and underpins a range of other GDPR requirements.
Before an organisation considers data minimisation, retention periods, security controls, or accountability, it must first be able to answer three questions:
- Do we have a lawful reason for processing this information?
- Are we treating people fairly?
- Are we being open and honest about what we are doing?

What Does Lawfulness, Fair and Transparent Mean?
Lawful Processing
To process personal data lawfully under GDPR, organisations must have a lawful basis for doing so. There are seven main lawful bases set out in the GDPR (a seventh having been recently added by the 2025 Data Use and Access Act). They are:
- Consent: Individuals willingly agree to their data being processed.
- Contractual Obligations: Data processing is required to fulfill a contract.
- Legal Obligations: Processing is necessary to comply with legal obligations.
- Vital Interests: Data processing is vital to protect someone’s life.
- Public Authority: Processing is performed as an official function or task.
- Legitimate Interests: Organisations have an identified legitimate interest in processing personal data, but it must not override individuals’ rights, sand must take steps to balance privacy with their data processing aims.
- Recognised legitimate interests: some things such as safeguarding are automatically considered to be legitimate uses of data and as such a balancing test is not needed.
Determining with lawful basis applies depends on the purpose you want the data for.
Special Category Data
Certain types of personal data get additional protections under the GDPR. These are known as special category data and include information such as:
- health related data
- information related to ethnicity
- religious, social or cultural beliefs
- criminal record data
Because these categories of data have special protection a further lawful basis is needed to process data of this type.
Fairness
While “lawfulness” asks if you have a legal basis to process data, fairness asks whether you are treating the individual honestly, reasonably, and in a way that respects their reasonable expectations.
In essence, fairness is about ensuring that you are not using personal data in a way that is detrimental, unexpected, or misleading to the individual.
Key Dimensions of Fairness
To determine if processing is fair, organisations must consider:
- Reasonable Expectations: Data should only be used in ways that a normal person would reasonably expect. If an individual provides their email address to receive a receipt, they would not reasonably expect to be signed up for a third-party marketing list. Using their data for that unexpected purpose is unfair.
- Avoiding Detriment: Processing must not result in unjustified adverse effects for the individual. This includes discrimination, manipulation, or causing unnecessary distress. If a process unfairly penalises a specific group, even if the processing is technically lawful, it violates the fairness principle.
- Power Imbalances: Fairness is particularly important where there is a power imbalance, such as between an employer and employee, or a dominant service provider and a consumer. Because the individual has little choice but to agree to the processing, the organisation has an enhanced duty to ensure the terms are not exploitative or unfair.
- Avoiding Deception (Transparency Link): Fairness and transparency go hand-in-hand. An organisation cannot be fair if it hides how it uses data or uses “dark patterns” (manipulative design) to trick users into giving consent. Fairness requires that you are open, honest, and do not mislead individuals about the consequences of their choices.
Why it Matters
Even if an organisation has a legal basis (like legitimate interests), that basis can be invalidated if the processing itself is fundamentally unfair. It prevents organisations from using data in ways that are technically legal but morally or ethically indefensible.
Key Questions
- Would individuals reasonably expect this processing?
- Could the processing cause harm?
- Is there a significant imbalance of power?
- Are vulnerable people involved?
- Are decisions being made responsibly?
Transparency
Organisations must be open and clear about how personal data are collected, used, stored, and shared.
The GDPR sets out that it should be clear to people that personal data concerning them are collected, used, and processed. The principle of transparency requires that any information and communication relating to the processing of those personal data be easily accessible and easy to understand, and that clear and plain language be used.
This links to fairness – if you are collecting and processing data about children or other vulnerable people you will need to consider how they will understand your data processing activities.
Crucially transparency requires that people are informed of this at the time data about them are collected.
Overall individuals should understand:
- what information is collected
- why it is collected
- how it will be used
- who it will be shared with
- how long it will be retained
- what rights they have
How Lawfulness, Fairness and Transparency Work Together
Imagine an online retailer collects customer email addresses to keep customers informed of deliveries.
Lawful?
The retailer has a lawful basis for processing this data, because it needs it to fulfil the contract between it and the customer.
Fair?
Using the addresses for unrelated purposes may be unfair. For example, using the emails for marketing purposes needs a separate lawful basis and must be explained in any privacy information. However, it still may not be data processing the customer expects.
Transparent?
If customers were not informed about the use of their emails for marketing purposes, transparency is missing as well as fairness.
The three elements of the first privacy principle should be considered together. A processing activity can fail this principle even if only one element is missing.
Applying the Principle Throughout the Information Lifecycle
Data processing happens throughout the information lifecycle so the first data privacy principles must be considered at each step and for each processing activity.
Data Collection
- Explain the purposes you need data for clearly, in a way your audience would understand.
- Identify lawful bases. For example, an online retailer might use the contractual basis to fulfil an order, legitimate interests or consent for marketing, and the statutory duty basis if it needs to check customers are over 18.
- Make the privacy information easily accessible.
Data Use
- Use information consistently with stated purposes, and not using it for other things that are not included in your privacy information
- Avoid unexpected processing by planning carefully for your data needs
Data Sharing
- Inform individuals when data are shared with other organisations and ensure the sharing is justified.
Data Retention
- Retain information only in line with retention periods and appropriate policies. If possible set out retention practices in your privacy statement.
Data Disposal
- Dispose of information securely, using a method appropriate to the sensitivity of the data and the vulnerability of data subjects. This does not need to be set out in your privacy statement, but it still must be fair.
Lawfulness, fairness and transparency should guide every stage of processing.
The Role of Privacy Notices
Privacy notices help organisations explain:
- who they are
- why they process personal data
- lawful bases
- recipients
- retention periods
- individual rights
Good privacy notices should be
- clear
- concise
- accessible
- easy to understand
Common Mistakes
Writing privacy notices solely for lawyers or regulators rather than for the people whose data are being processed.
One approach many organisations take is to have a more layered privacy notice:
- a simple web page setting out at a high level core data processing activities in line with the concept of lawful fair and transparent. An advantage of this is organisations can use videos or animations rather than text.
- A more detailed technical statement that goes into more depth for people who need it, perhaps in the form of a downloadable document
- The contact details of an organisation’s Data Protection Officer for any outstanding questions people may have.
Common Misconceptions
There are a number of errors organisations make with their privacy information that we have seen
We Have Consent, So Everything Is Fine
Consent is a lawful basis but that alone does not guarantee fairness. People must still have a full understanding of any data processing they are consenting to.
If It Is Legal, It Must Be Fair
Lawfulness and fairness are separate requirements and it does not follow that having a lawful basis for data processing means that processing is fair
People Never Read Privacy Notices
People do. And if people choose not to transparency is still required. If anyone raises a query or concern your privacy and transparency information will be a key tool you can refer to and rely on.
Employees Don’t Need Privacy Notices
Employees are data subjects too and should have privacy information provided to them whether separately or as part of your main transparency efforts.
Using a Generic Privacy Statement Template
A generic template will not cover all of your data processing because different lawful bases can apply to the same processing activity, such as marketing, and because every organisation’s data subjects are different. Every template must be adapted and be specific to your organisation.
- read more about common privacy statement mistakes here.
Practical Examples
Recruitment
Candidate data is often processed under the contractual lawful basis (your are considering offering a contract of employment) and the statutory duty basis (employers have a legal duty to check if people have the right to work in the UK).
Inform candidates how their information will be used, and how long it will be retained if candidates are unsuccessful. If you use AI to screen candidates or applications you must make this clear in your transparency information.
Employee Management
Personal data will be processed for employment purposes to deliver on employment contracts:
- Payroll
- Performance management, appraisal and monitoring
- Sickness absence management and occupational health
Employee focused privacy information will set out all of these uses and explain what they are for.
Customer Services
Customer data will be processed for a range of reasons. To fulfil a contract (including credit checks, payment and delivery), to market other products and services, and to seek feedback or reviews. Again this would rely on a mix of lawful bases: contractual; legitimate interests; and/or consent.
Provide clear explanations about data use to customers and make it readily available before they purchase anything or make an enquiry. You must ensure that if people do not give consent to activities like marketing you do not include them in your marketing materials.
CCTV
Inform individuals that monitoring is taking place and explain why. This can be done with signage but crucially that signage must be visible at or before the point people enter the area being filmed.
Demonstrating Compliance
Organisations are accountable for demonstrating their compliance with the first privacy principle. Evidence organisations may need to show compliance includes:
- privacy notices
- records of processing activities
- lawful basis assessments
- legitimate interests assessments
- DPIAs
- policies and procedures
- training records
- evidence of data destruction
Organisations should be able to demonstrate how they have considered lawfulness, fairness, and transparency as part of their processing activities throughout the information life cycle
Relationship to Other GDPR Privacy Principles
The principle of lawful, fair and transparent is one of several privacy principles and they do not sit in isolation. They interact with each other and support overall compliance. For example:
Purpose Limitation
Knowing what you do and do not process personal data for supports transparency.
Data Minimisation
Limiting the data you collect supports fairness.
Accountability
Requires evidence of compliance.
Lawfulness, fairness and transparency influences all the GDPR privacy principles and it in turn influenced by them.
Practical Checklist
Before processing personal data ask:
- Do we have a lawful basis?
- Would individuals reasonably expect this processing?
- Could the processing cause unfair impacts?
- Have we explained the processing clearly?
- Is the information accessible and understandable?
- Can we demonstrate our reasoning?
Conclusion
As the first data privacy principle lawfulness, fairness and transparency are the foundation of GDPR compliance. Organisations must be able to justify, explain, and defend their processing activities.
Effective compliance with this principle requires more than identifying a lawful basis. You must be reasonable and fair in your data collection and processing. Openness, trust, and responsible decision-making are key.
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: